SHPT-00-000690 - The Central Administration site must not be accessible from Extranet or Internet connections.

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

SharePoint must prevent the presentation of information system management-related functionality at an interface utilized by general, (i.e., non-privileged), users.

Central Administration is an application used to manage SharePoint system settings and the settings of the web applications running under SharePoint. The Central Administration application should be protected using a defense-in-depth approach. Regular users should not be able to access the Central Administration as the first line of defense. The second line of defense is that regular users do not have user ids defined in the Central Administration application.
NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Block outside Central Administration access.
Use IIS IP address restrictions, firewall, or other filtering solutions to limit access to the Central Administration site.

See Also

http://iasecontent.disa.mil/stigs/zip/Oct2015/U_Sharepoint_2010_V1R7_STIG.zip

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7, CAT|II, CCI|CCI-001083, Rule-ID|SV-36741r2_rule, STIG-ID|SHPT-00-000690, Vuln-ID|V-28281

Plugin: Windows

Control ID: 04e9f59eabc0db7430eddbf95467d37ef782d049ae31518c978853d688f828ca